N
Neon12mo ago
national-gold

create role error

Hi Tristan, It's a service account that automatically creates the role upon request. I'm not sure to how exactly this service account creates roles. Obviously the best course here is to create the role with password, but in my case with the service account that's not possible.
7 Replies
inland-turquoise
inland-turquoise12mo ago
no like, are you using the api, and if so what endpoint?
ambitious-aqua
ambitious-aqua11mo ago
Hi @Tristan Partin I'm not using the API. We create a user in the DB that has the abiltity to grant other users permissions. We then connect to the DB as that user and run a query to create a role and assign it to the user.
sensitive-blue
sensitive-blue11mo ago
Hi @Tristan Partin — more context on this: we're a Neon customer looking to use Apono. We're the end customer and Nivi from Apono is looking to figure out how to make their integration work with Neon. It seems like their platforms requires the ability to create roles without password. Not sure why that's not allowed on Neon. We'd love to be able to use Apono with Neon but unfortunately that's not possible because of this quirk in how Neon works. Is there a solution here?
Apono
Automate Database Access Management and Control
Automate on-demand, temporary access to databases with Apono to reduce downtime risk, protect customer data and PII and ensure least privilege
ambitious-aqua
ambitious-aqua11mo ago
@Tristan Partin any workaround we can use, anything in Neon config to allow the creation of passwordless roles?
inland-turquoise
inland-turquoise11mo ago
I've asked internally
fair-rose
fair-rose11mo ago
👋 I think we need to understand why Apono needs a password-less user. In general this isn't a good approach for security of the database system, which is why we don't allow it. Could you connect us with the Apono team? my email is bryan at neon.tech
ambitious-aqua
ambitious-aqua11mo ago
Hi Bryan thanks for you response. We're not creating a password-less user but rather a password-less role. We do create a user with a password and then assign it the password-less role. I'll connect you with the team here at Apono. Thanks!

Did you find this page helpful?